Background checks in recruitment can help companies reduce risks associated with fake candidates, embellished CVs or roles requiring a high level of trust. In Poland, however, this does not mean complete freedom to screen candidates. Employers should only collect information that is relevant to the position, necessary for the recruitment process and compliant with labour law and GDPR.
As a general rule, a company can verify contact details, qualifications, education, professional experience and employment history, but only when this is related to the role the candidate is applying for. Not every candidate’s consent legalises an additional background check, and certain information, such as criminal record data, can only be required when specific regulations provide for it.
That is why a legal background check in recruitment should not start with the question “what else can we check?” but rather with “is this information truly necessary to make a hiring decision for this specific role?”.
Article agenda:
1. Why do background checks in recruitment raise so many concerns today?
2. What data can an employer collect from a candidate?
3. Can you ask a candidate to show their ID?
4. Employment contract vs B2B: can you verify more under B2B cooperation?
5. Can a recruitment agency check more than the employer?
6. Can you create candidate blacklists?
7. Three principles of a legal background check
Why do background checks in recruitment raise so many concerns today?
Just a few years ago, background checks in Poland were mainly associated with large corporations, the financial sector or positions requiring a high level of trust. Today, the topic comes up much more often, especially in IT recruitment and processes run for technology companies.
The reasons are fairly obvious. The job market has become more remote, recruitment processes increasingly take place online, and companies more often deal with fake candidates, CV inconsistencies, artificially generated profiles and identity fraud attempts. From an organisation’s perspective, the need for greater caution is therefore understandable.
The problem begins when that caution turns into overly broad screening. This is particularly common in international companies that try to implement global background check procedures designed for other markets, such as the United States, the United Kingdom or India. What is standard practice in one jurisdiction may prove problematic in Poland from the perspective of the Labour Code, GDPR and candidate privacy protection.
In practice, background checks in recruitment become a point where three perspectives meet: company security, candidate rights and local regulations. And that is precisely why they require a well-designed process rather than automatic copying of corporate procedures.
What data can an employer collect from a candidate?
The starting point is Article 22¹ of the Labour Code, which defines the catalogue of data an employer can request from a person applying for employment. This includes, among others, identification and contact data, education, professional qualifications and employment history.
However, this does not mean that any information about a candidate’s education or work history is automatically permitted. The key factor is relevance. An employer should only ask about elements that have a genuine connection to the specific recruitment.
If a company is looking for someone for a managerial position, it can ask the candidate to confirm their team management experience. If it is recruiting a Java developer, it can verify experience in that technology, provided it is relevant to the role. However, it should not collect information about the candidate’s entire work history if part of that history has no connection to the requirements of the position.
This is an important distinction. A background check should not be a pretext for collecting data “just in case”. In recruitment, the principle of “better to have more information than less” can lead to violations. The reverse principle is safer: only collect what you can justify.
Candidate consent does not legalise everything
One of the most common myths about background checks is the belief that if a candidate gives consent, the company can check virtually anything.
In practice, consent does not work like a “magic wand”. It does not automatically turn an impermissible practice into a legal one. Particularly in the candidate–employer relationship, it is important to remember that the candidate is usually in a weaker position. They want the job, so they may agree to many things not because they genuinely want to share their data, but because they fear losing the chance of employment.
That is why, even if a candidate formally clicks consent for a background check, the company still needs to answer several questions:
- Is this information necessary for this recruitment?
- Is it related to the specific position?
- Is there a legal basis for processing it?
- Is the scope of verification proportionate?
- Does the candidate know exactly what will be checked and for what purpose?
If the answer is unclear, consent alone does not solve the problem. Particular caution is needed with sensitive data, criminal record information, private social media, debt history or other elements of the candidate’s private life.
When can you check a candidate’s criminal record?
The question about the KRK, or the National Criminal Register, regularly comes up in the context of background checks. Many companies would like to be certain that a candidate has no criminal record, especially if they will be working with data, finances, systems or enterprise clients.
In Poland, however, you cannot demand a criminal record certificate from every candidate simply because the company wants to reduce risk. Such a possibility must stem from specific regulations or the nature of the position as indicated in special legislation.
The situation is different for regulated roles, work with children, certain positions in the financial sector, public sector entities or areas requiring a high level of trust. In those cases, regulations may explicitly provide for a clean criminal record requirement.
But if a company is recruiting, for example, a copywriter, a marketing specialist or a standard technology role, the mere feeling that “it would be worth checking” is not enough. Even if the candidate agrees to provide the certificate, the employer should first establish whether they have the right to request such a document at all.
Can a company check references?
References are one of the most practical tools for verifying a candidate’s experience, but mistakes are easy to make here as well.
The safe approach is for the candidate to indicate the people the potential employer can contact. Ideally, the candidate should obtain their consent to share contact details beforehand. This way, reaching out to a former manager or colleague has a clear purpose and is connected to the recruitment process.
What is risky, however, is a situation where a recruiter independently searches for the candidate’s former manager on LinkedIn and calls them without the candidate’s knowledge. Firstly, this means discussing a third party without a clear basis. Secondly, the current or former employer may not know that the candidate is looking for a job. Thirdly, such a conversation may reveal information that the company should not be processing at all.
In practice, it is therefore worth treating references as part of the process that should be structured, transparent and limited to information relevant to the given role.
LinkedIn, Facebook, GitHub: what can you check?
Social media is one of the most problematic areas of background checks. Recruiters and hiring managers often assume that since something is public, it can be freely used in the recruitment process. This is an oversimplification.
LinkedIn is a special case because it is professional in nature. Candidates themselves publish information there about their experience, projects, companies and skills. If information from LinkedIn is inconsistent with the CV, the employer can ask the candidate for clarification. However, it is still worth exercising caution and not treating the profile as the sole source of truth.
The situation is different with Facebook, Instagram or other private channels. Information about lifestyle, views, family, holidays or private comments should not influence the recruitment decision. Even if a recruiter accidentally comes across such data, using it can lead to privacy protection issues, GDPR problems or discrimination claims.
The same applies to OSINT in the broad sense, or open-source intelligence gathering online. Verifying a candidate’s online activity may seem appealing, especially in the context of fake profiles, but it should be conducted very carefully. The further you move from information provided by the candidate themselves and the closer you get to their private life, the greater the legal risk.
Can you ask a candidate to show their ID?
Remote recruitment has made the question of identity verification increasingly common. Companies want to know whether they are speaking with the person who actually applied. In the era of fake candidates and remote processes, this is a real problem.
However, simply showing an ID to the camera is a sensitive area. An identity card contains data that is not always needed in recruitment, such as parents’ names or other information that goes beyond the basic purpose of confirming identity. An even greater problem would be requesting a scan of the ID or sending the document by email.
A more sensible direction involves solutions that allow identity confirmation without excessive data processing. Examples include tools based on identity verification through a trusted source, such as electronic banking or government applications, where the company only receives confirmation that the person is who they claim to be, without access to the full document.
This illustrates a broader trend: the problem of candidate verification should not be solved by collecting an ever-growing number of documents, but by designing processes that limit the scope of data to the minimum.
Employment contract vs B2B: can you verify more under B2B cooperation?
In Polish IT recruitment, some processes involve an employment contract while others involve B2B cooperation. This raises the question of whether under B2B a company can afford a broader background check.
The answer is: partially yes, but this does not mean complete freedom.
Under B2B, the same Labour Code restrictions do not directly apply, since there is no classic employee–employer relationship. However, personal data protection regulations, as well as the principles of relevance, purpose limitation and data minimisation, still apply. The candidate or contractor remains a natural person whose data is subject to protection.
This means that a company cannot justify any scope of screening simply by saying “it’s B2B”. It still needs to know why it is collecting specific information, whether it is necessary and how it will be used. Contractual freedom does not override GDPR obligations.
Can a recruitment agency check more than the employer?
This is a particularly important question for companies that use external recruitment partners. Sometimes there is a belief that if the employer cannot check something themselves, they can outsource it to an agency or an external background check vendor.
Such an approach is risky. An agency is not a “workaround” for the employer’s restrictions. If it acts on behalf of a specific client and for a specific recruitment, the scope of information collected must still result from the needs of that recruitment and applicable regulations.
Moreover, responsibility for the legality of the process may be distributed across several entities: the employer, the recruitment agency and the external vendor. It is not enough to say “the client required it” or “the vendor does this as standard”. Every participant in the process should know what data they process, on what basis, for what purpose and who has access to it.
The broader the scope of the background check, the more important contracts, authorisations, procedures, documentation and a clear definition of responsibilities become.
Can you create candidate blacklists?
In recruitment practice, there is sometimes a temptation to create internal lists of candidates the company no longer wants to engage with. The reasons vary: inconsistent CVs, suspected fraud, unprofessional behaviour, ghosting, false information.
The problem is that such a list usually contains personal data along with additional assessments about a specific person. If a note appears in the system such as “fraudster”, “do not contact” or “suspected fake candidate”, the company is processing information that can have real consequences for that person.
This is a very risky area from a GDPR perspective. A candidate has the right to ask what data the company processes about them. If the system contains imprecise, evaluative or undocumented notes, the organisation may have difficulty justifying them.
This does not mean that recruiters cannot document the process. It does mean, however, that notes should be factual, proportionate, limited to the purpose of recruitment and free of unnecessary judgements. Instead of “fake candidate” without context, it is better to record specific, defensible information, such as “the candidate refused to explain discrepancies between the CV and the information provided during the interview”.
Three principles of a legal background check
The most important takeaway from the conversation is simple: a background check in recruitment should be designed from the end, meaning from the question of whether the company will be able to defend the scope of collected data in the event of an inspection, complaint or dispute.
Firstly, every piece of information should be related to the position. If we cannot explain why a given piece of information is needed to assess a candidate for a specific role, we probably should not be collecting it.
Secondly, the scope of verification should be proportionate. Recruitment for a regulated role, a position with access to financial data or work with children looks different from a standard marketing, administrative or technology recruitment.
Thirdly, candidate consent does not solve everything. Even if the candidate agrees to a background check, the company must still act in accordance with the law, the principle of data minimisation and information obligations.
Background check in recruitment: common sense matters more than automatic procedures
A background check can be a valuable part of the recruitment process, especially in times of remote interviews, fake candidates and growing security requirements. However, it should not turn into automatic screening of candidates according to a global template.
The greatest risk does not lie in the screening itself, but in the lack of proportion. A company that verifies experience needed for a given role operates differently from one that collects documents, checks private social media and requires certificates “just in case”.
In the Polish context, a safe background check is one that is specific, justified, transparent and limited to the purpose of recruitment. A well-designed process can protect the company. A poorly designed one can become a source of legal problems, loss of candidate trust and unnecessary risk for the organisation.
If you would like to listen to our conversation on this topic, we invite you to watch our webinar with expert Karolina Gradowska-Kania.